Description
Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Landed Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Landed Cost Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Landed Cost Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle Landed Cost Management that allows an attacker with only low privileges and network access via HTTP to compromise the application. The flaw permits the attacker to read critical data, obtain complete access to the data available to the application, and perform unauthorized updates, inserts or deletes. The impact is a loss of confidentiality for sensitive cost data and a compromise of data integrity.

Affected Systems

The affected vendor is Oracle Corporation, specifically the Oracle Landed Cost Management component of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are vulnerable.

Risk and Exploitability

The CVSS 3.1 Base Score of 7.1 indicates a high severity, with confidentiality impact rated high and integrity impact low. The attack vector is network, available from any host that can reach the HTTP interface, and the required privileges are low. The EPSS score of 0.00316 indicates a very low, but non-zero, likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The combination of a network-based exploitation path and low requirement for privileges raises the likelihood of actual attacks, especially in environments where the Oracle Landed Cost Management service is exposed to untrusted hosts.

Generated by OpenCVE AI on August 21, 2026 at 08:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or fix released by Oracle for Landed Cost Management 12.2.3 through 12.2.15 to eliminate the vulnerability.
  • If a patch cannot be applied immediately, restrict HTTP access to the application by allowing traffic only from trusted IP ranges or requiring VPN authentication.
  • Enable logging and auditing for all data modification operations, and monitor logs for unauthorized update, insert, or delete activity.

Generated by OpenCVE AI on August 21, 2026 at 08:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit in Oracle Landed Cost Management
Weaknesses CWE-200
CWE-284

Fri, 21 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Allows Unauthorized Data Access in Oracle Landed Cost Management
Weaknesses CWE-284

Wed, 19 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Allows Unauthorized Data Access in Oracle Landed Cost Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Landed Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Landed Cost Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Landed Cost Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle landed Cost Management
CPEs cpe:2.3:a:oracle:landed_cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle landed Cost Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Landed Cost Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:22:15.012Z

Reserved: 2026-08-04T22:06:34.600Z

Link: CVE-2026-70833

cve-icon Vulnrichment

Updated: 2026-08-24T14:07:55.637Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:38.660

Modified: 2026-08-28T14:46:04.297

Link: CVE-2026-70833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control